This guide is general legal information, not legal advice, and does not create an attorney–client relationship. Rules change and vary by state — verify current requirements with official sources or a licensed attorney.
Every fintech runs on data it does not really own: account numbers, balances, transaction histories, identity documents, device signals. U.S. law regulates that data through several overlapping regimes rather than one statute — the Gramm-Leach-Bliley Act (GLBA) and the FTC's Safeguards Rule at the federal level, New York's Part 500 cybersecurity regulation for licensed financial companies, and a growing set of state consumer privacy laws around the edges. The compliance question is less "which law applies?" than "how do we run one program that satisfies all of them?"
Rather than march statute by statute, this guide builds the framework the way a compliance lead would: map the obligations, then organize them into five operating pillars.
Key takeaways
- Most fintechs are "financial institutions" under GLBA, which imposes both privacy-notice duties and, through the FTC Safeguards Rule, a detailed written information security program.
- Since May 13, 2024, Safeguards Rule–covered companies must report breaches involving unencrypted information of 500 or more consumers to the FTC within 30 days of discovery.
- New York's 23 NYCRR Part 500 adds prescriptive requirements — CISO accountability, 72-hour incident notice, annual certifications — for companies licensed by NYDFS, with amended requirements phased in through November 2025.
- State comprehensive privacy laws mostly exempt GLBA-regulated data or entities, but the exemptions differ, and non-financial data (marketing, web analytics) often remains covered.
- Regulators judge programs by governance and documentation: risk assessments, designated accountability, vendor oversight, and tested incident response.
First, map the obligations
Four sources of law do most of the work for a U.S. fintech:
- GLBA privacy rules. Financial institutions must give consumers privacy notices describing information sharing and, for some sharing with nonaffiliated third parties, an opt-out. The CFPB's Regulation P implements this for most nonbank financial companies.
- The FTC Safeguards Rule. GLBA's security half. It requires a comprehensive written information security program, and the FTC's business guidance spells out required elements — from a designated "qualified individual" to encryption and multifactor authentication. It covers nonbank financial institutions under FTC jurisdiction; banks answer to their prudential regulators under parallel interagency standards.
- NYDFS Part 500. If the company holds a New York license — including a money transmitter or virtual currency license — the DFS cybersecurity regulation applies, with obligations that go beyond the federal baseline.
- State privacy laws. California's CCPA and a lengthening list of state analogues grant consumers rights over personal information generally. Their financial-data exemptions are real but incomplete, as discussed below.
Add sector-specific overlays where relevant — the FCRA for credit data, the card network rules that arrive by contract rather than by statute — where PCI DSS obligations and the card brands' liability-shift rules ride on the merchant and processor agreements a fintech signs — and the UDAAP risk that follows any gap between privacy promises and practice, covered in our guide to CFPB enforcement risk for fintechs.
Pillar 1: A written security program that matches the Safeguards Rule
The Safeguards Rule is effectively a federal checklist for your security program. Core required elements include:
- Designate a qualified individual accountable for the program, reporting in writing to the board or governing body.
- Run and document a written risk assessment, and refresh it as the business changes.
- Implement access controls and maintain an inventory of data, systems, and where customer information lives.
- Encrypt customer information in transit and at rest (or document approved compensating controls).
- Require multifactor authentication for access to systems containing customer information.
- Adopt secure development practices, change management, and logging/monitoring of authorized user activity.
- Test controls — continuous monitoring or annual penetration testing plus periodic vulnerability assessments.
- Train staff, oversee service providers by contract, and maintain a written incident response plan.
- Dispose of customer information securely when it is no longer needed.
Very small operations (generally those maintaining information on fewer than 5,000 consumers) are excused from a handful of written-documentation elements, but not from the program itself.
Pillar 2: Breach detection and notification, with clocks you can actually meet
Notification duties now stack. Under the Safeguards Rule amendment that took effect May 13, 2024, a covered nonbank must notify the FTC as soon as possible and no later than 30 days after discovering a "notification event" — unauthorized acquisition of unencrypted customer information involving at least 500 consumers — via the FTC's online portal, which publishes the reports. The FTC's announcement and the underlying Federal Register rule detail the trigger and contents. NYDFS-licensed companies must notify DFS within 72 hours of certain cybersecurity events. Separately, all 50 states have consumer breach notification statutes with their own triggers and timelines, and contracts with bank partners typically add notice duties measured in hours.
Watch the deadline: The clocks run from discovery, not from completed forensics. An incident response plan should pre-assign who determines "discovery," who counts affected consumers, and who owns each regulator's filing — decisions that are painful to improvise mid-incident.
Pillar 3: Privacy notices and state-law rights
GLBA requires initial (and in some cases annual) privacy notices and opt-outs for certain sharing. State comprehensive privacy laws then apply to whatever GLBA does not cover — and the carve-outs differ in kind. Many states exempt entire entities subject to GLBA; California's CCPA, by contrast, exempts GLBA-covered data but not the business itself, so marketing lists, website analytics, job-applicant data, and other non-GLBA personal information can remain subject to consumer rights requests. The California Attorney General's CCPA resource page outlines the rights involved: access, deletion, correction, and opt-outs from sale or sharing.
Practically, that means a fintech needs a data map that tags each dataset by regime — GLBA customer information, state-law personal information, or both — and a request-handling workflow for the state-law slice. Deceptive statements in a privacy policy are independently actionable by the FTC, so notices should describe what actually happens, not what the template says.
Pillar 4: Vendors, partners, and the data supply chain
Customer data rarely stays inside the company. Cloud hosts, data aggregators, KYC vendors, card processors, and analytics tools all touch it, and every regime holds the fintech responsible for its providers: the Safeguards Rule requires selecting capable service providers and binding them by contract; Part 500 requires a third-party security policy; bank partners flow down their own regulators' third-party risk expectations, a dynamic explored in our article on bank–fintech partnerships. Diligence questionnaires, security addenda, audit rights, breach-notice clauses measured in hours, and offboarding data-return terms are the standard toolkit. The same discipline supports the customer-identification and monitoring duties described in our AML and KYC primer, which depend on the integrity of vendor-held data.
Pillar 5: Governance, certification, and proof
What separates a program that survives an exam from one that does not is usually evidence. NYDFS requires an annual certification of material compliance (or an acknowledgment of noncompliance) signed at a senior level, and its amended regulation phased in heightened requirements — expanded multifactor authentication, asset inventories, and stricter access controls — through November 1, 2025. The Safeguards Rule requires written reporting to the board at least annually. Examiners and litigants alike will ask for the artifacts: the current risk assessment, penetration test results and remediation tickets, training logs, vendor files, and incident post-mortems. Companies preparing for licensing or diligence should treat these documents as deliverables with owners and refresh dates, not as one-time projects — the same posture that serves them across the rest of the U.S. fintech regulatory landscape.
Frequently asked questions
Is a fintech startup really a "financial institution" under GLBA?
Usually, yes. GLBA defines financial institutions functionally — companies significantly engaged in financial activities such as lending, payments, financial advisory services, or brokering — regardless of size or charter. A pre-revenue app that handles consumer financial data in connection with such services should assume GLBA applies and confirm the analysis with counsel.
We encrypt everything. Do breach notification duties still matter?
Yes, though encryption helps significantly. The FTC's trigger covers unauthorized acquisition of unencrypted customer information — and information counts as unencrypted if the attacker also obtained the key. State statutes vary in how they treat encrypted data. Strong encryption plus key management can keep many incidents below notification thresholds, but each regime's trigger must be checked.
Do state privacy laws like the CCPA apply if we comply with GLBA?
Often partially. Many states exempt GLBA-regulated entities entirely, but California exempts only GLBA-covered data, leaving other personal information — marketing, analytics, applicant data — subject to consumer rights. Because exemption structures differ state to state, a data map that classifies each dataset by applicable regime is the only reliable answer.
Who enforces these rules against nonbank fintechs?
Primarily the FTC (Safeguards Rule and deceptive privacy practices), the CFPB (Regulation P and UDAAP), state attorneys general (privacy and breach statutes), and NYDFS for its licensees. Private lawsuits add exposure in some states, including California's limited private right of action for certain breaches.
From checklist to operating discipline
The regimes overlap enough that one well-governed program can serve them all: a single risk assessment feeding a single control set, with regime-specific overlays for notices, filings, and certifications. Sensible next steps are to build the data map, benchmark the current program against the Safeguards Rule element list, pre-write the breach decision tree with every applicable clock, and calendar the certifications. For adjacent obligations that share the same infrastructure, browse the rest of our fintech law coverage. As always, this is general information rather than legal advice, and requirements as of August 2026 should be verified against current rules before relying on them.
Sources & further reading
- FTC — FTC Safeguards Rule: What Your Business Needs to Know
- FTC Business Blog — Safeguards Rule notification requirement now in effect (May 2024)
- Federal Register — Standards for Safeguarding Customer Information (breach notification amendment)
- New York DFS — Cybersecurity Resource Center (23 NYCRR Part 500)
- California Attorney General — California Consumer Privacy Act (CCPA)